> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hookie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Records received by one webhook, optionally through a saved view

> Top-level alias: GET /admin/api/webhooks/{id}/records. Readable by any role. Only GET is routed here; other methods on this path fall through the webhook router to 405.



## OpenAPI

````yaml /openapi.json get /admin/api/projects/{pid}/webhooks/{id}/records
openapi: 3.1.0
info:
  title: Hookie API
  version: 1.0.0
  summary: Capture, route and deliver webhooks.
  description: >-
    Hookie exposes three HTTP surfaces.


    **Ingest + streaming** is the public plane. A path-form endpoint URL
    authenticates by its own high-entropy slug — there is no key, token or
    cookie — and an `ik_live_…` ingest key authenticates the `/v1/*` routes.
    Whenever the URL names a dataset the payload is stored whole into it;
    project mapping rules are evaluated on exactly one shape, `POST
    /v1/ingest/{ingest_key}` with no dataset segment.


    **The customer portal API** is a separate, token-authed surface for your end
    customers, scoped to one portal and one customer.


    **The admin API** drives the console. It accepts either a browser session or
    an OAuth bearer token from a connected coding agent — the same routes, the
    same validation, the same audit trail. An agent's authority is its user's
    workspace role narrowed to the scopes granted in the console.


    This document is generated from the request handlers and adversarially
    verified against them.
  contact:
    name: Hookie
    url: https://hookie.ai
  license:
    name: Proprietary
    url: https://hookie.ai/legal/terms
servers:
  - url: https://app.hookie.ai
    description: Production
  - url: https://app.preview.hookie.ai
    description: Preview
security: []
tags:
  - name: Ingest
    description: Send events to Hookie.
  - name: Streaming
    description: Tail events in real time over SSE or WebSocket.
  - name: Portal
    description: Token-authed surface for your end customers.
  - name: Projects
    description: Projects and their settings.
  - name: Routing
    description: Rules, endpoints, datasets and records.
  - name: Delivery
    description: Destinations, deliveries and replay.
  - name: Workflows
    description: Multi-step workflows, triggers and AI agents.
  - name: Observability
    description: Search, correlation, stats and the audit log.
  - name: Workspace
    description: Members, connected agents, SSO and billing.
paths:
  /admin/api/projects/{pid}/webhooks/{id}/records:
    get:
      tags:
        - Records
      summary: Records received by one webhook, optionally through a saved view
      description: >-
        Top-level alias: GET /admin/api/webhooks/{id}/records. Readable by any
        role. Only GET is routed here; other methods on this path fall through
        the webhook router to 405.
      operationId: listWebhookRecords
      parameters:
        - name: pid
          in: path
          required: true
          description: Project id (UUID) belonging to the caller workspace.
          schema:
            type: string
        - name: id
          in: path
          required: true
          description: Webhook id.
          schema:
            type: string
        - name: view
          in: query
          required: false
          description: >-
            Record-view id to shape and sort the rows. The view must belong to
            this webhook.
          schema:
            type: string
        - name: limit
          in: query
          required: false
          description: >-
            Row cap. Non-numeric or non-positive values fall back to 200;
            anything above 1000 is clamped to 1000.
          schema:
            type: integer
            minimum: 1
            maximum: 1000
            default: 200
      responses:
        '200':
          description: >-
            Rows for the webhook. Without a view, every row is the record meta
            columns plus its whole flattened payload and columns is the
            discovered key set. With a view, each row carries _id plus exactly
            the view columns (missing keys become null), sorted in SQL by the
            view sort key. available_columns is always the full discovered set.
          content:
            application/json:
              schema:
                type: object
                required:
                  - webhook_id
                  - view
                  - columns
                  - available_columns
                  - rows
                  - count
                properties:
                  webhook_id:
                    type: string
                  view:
                    type:
                      - object
                      - 'null'
                    description: The applied view in list shape (snake_case), or null.
                    properties:
                      id:
                        type: string
                      webhook_id:
                        type: string
                      name:
                        type: string
                      columns:
                        type: array
                        items:
                          type: object
                          properties:
                            key:
                              type: string
                            label:
                              type: string
                      sort_key:
                        type:
                          - string
                          - 'null'
                      sort_dir:
                        type: string
                        enum:
                          - asc
                          - desc
                      is_default:
                        type: boolean
                      created_at:
                        type: string
                        format: date-time
                      updated_at:
                        type:
                          - string
                          - 'null'
                        format: date-time
                  columns:
                    type: array
                    items:
                      type: object
                      required:
                        - key
                        - label
                      properties:
                        key:
                          type: string
                        label:
                          type: string
                  available_columns:
                    type: array
                    items:
                      type: string
                    description: Includes the meta columns _id, _received_at and _source.
                  rows:
                    type: array
                    items:
                      type: object
                      additionalProperties: true
                  count:
                    type: integer
        '401':
          description: >-
            Not signed in, or the agent bearer token is invalid, unknown or
            revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            Email domain not allowed for the workspace, or an agent token
            granted no Hookie scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            Webhook not found, or View not found for the named view id on this
            webhook.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - session: []
        - bearerAuth: []
components:
  schemas:
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable reason.
        retry_after:
          type: integer
          description: Seconds to wait. Present on 429.
        upgrade_url:
          type: string
          format: uri
          description: Present only on a monthly-quota 429.
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: hookie_session
      description: >-
        The console's sealed session cookie, set by WorkOS AuthKit. Mutating
        requests also require the `X-Requested-With` CSRF header.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        An OAuth 2.1 access token from a connected agent, audienced at the
        `/mcp` resource URI. The agent acts as its user, with that user's role
        narrowed to the granted `hookie:*` scopes. No CSRF header is required —
        a bearer token is not ambient credentials.

````